This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to thefollowing package versions:

Ubuntu 6.06 LTS: firefox 1.5.dfsg+1.5.0.14~prepatch071125a-0ubuntu1

Ubuntu 6.10: firefox 2.0.0.10+0nobinonly-0ubuntu0.6.10

Ubuntu 7.04: firefox 2.0.0.10+1nobinonly-0ubuntu1

Ubuntu 7.10: firefox 2.0.0.10+2nobinonly-0ubuntu1.7.10.1

After a standard system upgrade you need to restart Firefox to effectthe necessary changes.

Details follow:

It was discovered that Firefox incorrectly associated redirected sitesas the origin of "jar:" contents. A malicious web site could exploit thisto modify or steal confidential data (such as passwords) from other websites. (CVE-2007-5947)

Various flaws were discovered in the layout and JavaScript engines. Bytricking a user into opening a malicious web page, an attacker couldexecute arbitrary code with the user's privileges. (CVE-2007-5959)

Gregory Fleischer discovered that it was possible to use JavaScript tomanipulate Firefox's Referer header. A malicious web site could exploitthis to conduct cross-site request forgeries against sites that reliedonly on Referer headers for protection from such attacks. (CVE-2007-5960)